
Aklamator Woocommerce Promotion Security & Risk Analysis
wordpress.org/plugins/aklamator-woocommerce-promotionAklamator Woocommerce Promotion plugin will make widget and populate it with products from your Woocommerce web shop. Widget is showing product image, …
Is Aklamator Woocommerce Promotion Safe to Use in 2026?
Generally Safe
Score 85/100Aklamator Woocommerce Promotion has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The aklamator-woocommerce-promotion v2.1.1 plugin exhibits a generally strong security posture in several key areas, particularly regarding its limited attack surface. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, significantly reducing the opportunities for external interaction. The absence of known CVEs and a clean vulnerability history further contribute to a positive security impression. The plugin also exclusively uses prepared statements for its SQL queries, which is a critical best practice. However, there are notable concerns. The low percentage of properly escaped output (5%) is a significant weakness, indicating a high potential for Cross-Site Scripting (XSS) vulnerabilities where user-supplied data might be rendered without adequate sanitization. The presence of a single external HTTP request, while not inherently malicious, warrants attention as it could be a vector for information disclosure or further attacks if not handled securely. The lack of nonce checks and capability checks on entry points, coupled with the limited output escaping, suggests that authenticated users could potentially trigger unintended actions or inject malicious scripts.
In conclusion, while the plugin excels in minimizing its direct attack surface and adhering to secure database practices, the substantial risk of XSS due to poor output escaping and the potential for privilege escalation or unauthorized actions due to missing authorization checks are significant drawbacks. The single external HTTP request also adds a layer of risk that requires careful scrutiny. The plugin's strengths lie in its limited entry points and safe SQL handling, but these are overshadowed by the weaknesses in output sanitization and authorization, necessitating caution.
Key Concerns
- Low percentage of properly escaped output
- No nonce checks on entry points
- No capability checks on entry points
- External HTTP request without explicit context
Aklamator Woocommerce Promotion Security Vulnerabilities
Aklamator Woocommerce Promotion Release Timeline
Aklamator Woocommerce Promotion Code Analysis
Bundled Libraries
Output Escaping
Aklamator Woocommerce Promotion Attack Surface
WordPress Hooks 10
Maintenance & Trust
Aklamator Woocommerce Promotion Maintenance & Trust
Maintenance Signals
Community Trust
Aklamator Woocommerce Promotion Alternatives
TI WooCommerce Wishlist
ti-woocommerce-wishlist
Boost your sales with a free WooCommerce Wishlist feature. Let your customers save and share their favorite products!
Continue Shopping for WooCommerce
continue-shopping-for-woocommerce
Easily change the 'Continue Shopping' link when redirected to the Cart after adding a Product.
Social Shop for WooCommerce
facebook-shop-by-storeyacom
This plugin will import your Woocommerce store to Facebook in a couple of minutes, with no development or design skills required.
Continue Shopping Anywhere for WooCommerce
continue-shopping-anywhere-for-woocommerce
Adds a continue shopping link on any woocommerce page. You can also customize this link.
Wishlist for WooCommerce
th-wishlist
A modern wishlist plugin for WooCommerce. Allows users to add products to a wishlist, view, and manage them.
Aklamator Woocommerce Promotion Developer Profile
7 plugins · 50 total installs
How We Detect Aklamator Woocommerce Promotion
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/aklamator-woocommerce-promotion/aklamatorWoo-pr.phpHTML / DOM Fingerprints
AKLAWOO_PR_PLUGIN_NAMEAKLAWOO_PR_PLUGIN_DIRAKLAWOO_PR_PLUGIN_URL<productphoto></productphoto><price></price>